Material Dashboard <= 1.4.10 - Missing Authorization to Unauthenticated Task Enumeration, Execution, and Deletion
high
The Material Dashboard plugin for WordPress is vulnerable to unauthorized access and modification of data due to missing capability checks on the amd_ajax_target_task_manager() function in all versions up to, and including, 1.4.10. This makes it possible for unauthenticated attackers to enumerate all scheduled tasks (p...
- CVSS:
- 7.3
- Affected:
- up to 1.4.10
- Fixed in:
- 1.4.11
- Disclosed:
- Aug 4, 2026
CVE-2026-6079 on NVD →
Material Dashboard <= 1.4.6 - Unauthenticated Privilege Escalation
critical
The Material Dashboard plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.4.6. This is due to the plugin not utilizing sufficiently random values in the publicAjaxHandler() function. This makes it possible for unauthenticated attackers to elevate their privileges to that...
- CVSS:
- 9.8
- Affected:
- up to 1.4.6
- Fixed in:
- 1.4.7
- Disclosed:
- Apr 14, 2025
CVE-2025-32486 on NVD →
Material Dashboard [material-dashboard] < 1.4.6
unknown
[en] Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ho3einie Material Dashboard allows PHP Local File Inclusion. This issue affects Material Dashboard: from n/a through 1.4.5.
- Affected:
- up to 1.4.6
- Fixed in:
- 1.4.6
- Disclosed:
- Apr 11, 2025
CVE-2025-31014 on NVD →
Material Dashboard <= 1.4.5 - Authenticated (Subscriber+) Local File Inclusion
high
The Material Dashboard plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.4.5. This makes it possible for authenticated attackers, with subscriber-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those fil...
- CVSS:
- 8.8
- Affected:
- up to 1.4.5
- Fixed in:
- 1.4.6
- Disclosed:
- Apr 9, 2025
CVE-2025-31014 on NVD →
Material Dashboard <= 1.4.5 - Unauthenticated Local File Inclusion
critical
The Material Dashboard plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.4.5. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access c...
- CVSS:
- 9.8
- Affected:
- up to 1.4.5
- Fixed in:
- 1.4.6
- Disclosed:
- Apr 1, 2025
CVE-2025-31097 on NVD →
Material Dashboard [material-dashboard] < 1.4.6
unknown
[en] Authentication Bypass Using an Alternate Path or Channel vulnerability in ho3einie Material Dashboard allows Authentication Bypass. This issue affects Material Dashboard: from n/a through 1.4.5.
- Affected:
- up to 1.4.6
- Fixed in:
- 1.4.6
- Disclosed:
- Apr 1, 2025
CVE-2025-31095 on NVD →
Material Dashboard [material-dashboard] < 1.4.6
unknown
[en] Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ho3einie Material Dashboard allows PHP Local File Inclusion. This issue affects Material Dashboard: from n/a through 1.4.5.
- Affected:
- up to 1.4.6
- Fixed in:
- 1.4.6
- Disclosed:
- Apr 1, 2025
CVE-2025-31097 on NVD →
Material Dashboard <= 1.4.5 - Unauthenticated Privilege Escalation
critical
The Material Dashboard plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.4.5. This makes it possible for unauthenticated attackers to elevate their privileges to that of an administrator.
- CVSS:
- 9.8
- Affected:
- up to 1.4.5
- Fixed in:
- 1.4.6
- Disclosed:
- Mar 28, 2025
CVE-2025-31095 on NVD →
Material Dashboard [material-dashboard] < 1.4.7
unknown
- Affected:
- up to 1.4.7
- Fixed in:
- 1.4.7
CVE-2025-32486 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database